Vulnerabilities & Exploits · Misconfiguration

NVIDIA DCGM Exporter exposes GPU fleets to recon

The Register reported that Nvidia fixed CVE-2026-47483 in September after researchers at Lava found about 2,100 internet-exposed DCGM Exporter servers, spanning roughly 300 organizations and 12,000 GPU UUIDs.

DCGM Exporter serves GPU hardware IDs, utilization, memory, power, and error events over plaintext HTTP with no login, so anyone who can reach it can read the telemetry; on busy hosts, repeated unauthenticated requests can also exhaust memory and crash the monitoring service. Lava also found that about a quarter of exposed hosts leaked Go pprof profiling data, adding more runtime detail to the same exposure.

For AI and HPC operators, the lasting issue is whether telemetry sits on an internet-reachable host at all: exposed metrics can map GPU inventory, reveal workload activity, and give attackers a low-noise way to pick targets before touching the workloads themselves.

1 source · Oct 8

CVE-2026-47483

NVD KEV

CVSS 8.2 HIGH: nVIDIA DCGM Exporter for all platforms contains a vulnerability in the /debug/pprof endpoints, where an attacker… EPSS 0.6% (44th percentile).

Timeline

Sources

Part of the PlainSec briefing for 2026-10-08

Every edition of this story: NVIDIA DCGM Exporter exposes GPU fleets to recon

More from today